# Latest

**URL:** https://discuss.elastic.co/latest.md?page=491

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 492

---

## [Filebeat large number of files opened](https://discuss.elastic.co/t/filebeat-large-number-of-files-opened/346433)

<div class="topic-metadata">

**Author:** [@ansamHox](https://discuss.elastic.co/u/ansamHox)\
**Replies:** 1\
**Last updated:** [November 6, 2023, 2:49pm UTC](https://discuss.elastic.co/t/filebeat-large-number-of-files-opened/346433 "2023-11-06T14:49:29Z")

</div>

Have issue on 1 machine sending logs from filebeat to kafka, it's lagging a lot and restarting a filebeat takes more than 45 minutes to completely restart it. - clean\_inactive: 18h close\_removed: true close\_inactive…

---

## [Advance logic alter rules (if "A" happens look for "B"](https://discuss.elastic.co/t/advance-logic-alter-rules-if-a-happens-look-for-b/346529)

<div class="topic-metadata">

**Author:** [@B-Rad](https://discuss.elastic.co/u/B-Rad)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 1:50pm UTC](https://discuss.elastic.co/t/advance-logic-alter-rules-if-a-happens-look-for-b/346529 "2023-11-06T13:50:31Z")

</div>

When creating an alert rule is it possible to add some more advanced logic or additional criteria if the first query is triggered? For example, I have authentication logs from our Idp I have an alert rule set for pot…

---

## [What is the purpose to clone the Event's fields so many times in processing event](https://discuss.elastic.co/t/what-is-the-purpose-to-clone-the-events-fields-so-many-times-in-processing-event/346526)

<div class="topic-metadata">

**Author:** [@qshuai](https://discuss.elastic.co/u/qshuai)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 1:28pm UTC](https://discuss.elastic.co/t/what-is-the-purpose-to-clone-the-events-fields-so-many-times-in-processing-event/346526 "2023-11-06T13:28:03Z")

</div>

There are many times to Clone Event's fields in processing event. The method Clone is: // Clone returns a copy of the MapStr. It recursively makes copies of inner // maps. func (m MapStr) Clone() MapStr { result := Map…

---

## [Extra Volume attached to elasticsearch but not not able to use](https://discuss.elastic.co/t/extra-volume-attached-to-elasticsearch-but-not-not-able-to-use/346512)

<div class="topic-metadata">

**Author:** [@vikascateina](https://discuss.elastic.co/u/vikascateina)\
**Replies:** 1\
**Last updated:** [November 6, 2023, 12:42pm UTC](https://discuss.elastic.co/t/extra-volume-attached-to-elasticsearch-but-not-not-able-to-use/346512 "2023-11-06T12:42:49Z")

</div>

Hi, I have attached 50 gb of volume to the ec2 instance of ecs in which elasticsearch service is running.But after running GET /\_cat/allocation?v in elasticsearch shards disk.indices disk.used disk.avail disk.total dis…

---

## [Use index action to write to multiple indices](https://discuss.elastic.co/t/use-index-action-to-write-to-multiple-indices/346369)

<div class="topic-metadata">

**Author:** [@rorii](https://discuss.elastic.co/u/rorii)\
**Replies:** 1\
**Last updated:** [November 6, 2023, 12:34pm UTC](https://discuss.elastic.co/t/use-index-action-to-write-to-multiple-indices/346369 "2023-11-06T12:34:11Z")

</div>

I have following action in my watcher: "actions": { "writetoindex": { "transform": { "script": { "id": "my\_tranform\_script", } } "index": { "index": "myindex…

---

## [Clearing the search context manually after reindexing is done](https://discuss.elastic.co/t/clearing-the-search-context-manually-after-reindexing-is-done/346517)

<div class="topic-metadata">

**Author:** [@Achyut\_Muley](https://discuss.elastic.co/u/Achyut_Muley)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 11:28am UTC](https://discuss.elastic.co/t/clearing-the-search-context-manually-after-reindexing-is-done/346517 "2023-11-06T11:28:36Z")

</div>

We have a shell script which takes the name of an index and then reindexes it. We are using ES 7.17.0 The reindex command- response=$(curl -u $CREDENTIALS -X POST "$PROTOCOL://$HOST:9200/\_reindex?slices=50&refresh&wai…

---

## [About ES8.10.4 pytorch\_inference](https://discuss.elastic.co/t/about-es8-10-4-pytorch-inference/346513)

<div class="topic-metadata">

**Author:** [@jaeho](https://discuss.elastic.co/u/jaeho)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 10:37am UTC](https://discuss.elastic.co/t/about-es8-10-4-pytorch-inference/346513 "2023-11-06T10:37:31Z")

</div>

Hello, I'm using Elasticsearch 8.10.4. I'm aiming to perform vector searches using a custom model through eland. You can find more details on this at NLP를 배포하는 방법: 텍스트 임베딩 및 벡터 검색 | Elastic Blog. I'm facing a long inde…

---

## [Metricbeat readiness for production, and how to configure the MSI package?](https://discuss.elastic.co/t/metricbeat-readiness-for-production-and-how-to-configure-the-msi-package/346511)

<div class="topic-metadata">

**Author:** [@mshwf](https://discuss.elastic.co/u/mshwf)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 10:15am UTC](https://discuss.elastic.co/t/metricbeat-readiness-for-production-and-how-to-configure-the-msi-package/346511 "2023-11-06T10:15:54Z")

</div>

I want to use Metricbeat to instrument one of our services. Firstly, I tried APM, but found we can't use it with custom metrics (our counters, gauges... etc.). So, I'm having a look at Metricbeat, it seems to offer what …

---

## [Prometheus exporter for Elasticsearch version 7.17.14](https://discuss.elastic.co/t/prometheus-exporter-for-elasticsearch-version-7-17-14/346510)

<div class="topic-metadata">

**Author:** [@tusharnemade](https://discuss.elastic.co/u/tusharnemade)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 10:12am UTC](https://discuss.elastic.co/t/prometheus-exporter-for-elasticsearch-version-7-17-14/346510 "2023-11-06T10:12:44Z")

</div>

Hello Team: I have upgraded Elasticsearch to version 7.17.14. We are using Prometheus - Grafana Dashboard to monitor the metrics of Elasticsearch Cluster and its Machine. I am unable to find Prometheus Exporter for El…

---

## [Kibana not working properly](https://discuss.elastic.co/t/kibana-not-working-properly/346028)

<div class="topic-metadata">

**Author:** [@chatim](https://discuss.elastic.co/u/chatim)\
**Replies:** 7\
**Last updated:** [November 6, 2023, 9:56am UTC](https://discuss.elastic.co/t/kibana-not-working-properly/346028 "2023-11-06T09:56:03Z")

</div>

Hello, I'm running a dockerized elastic cluster composed of 3 master and 3 data nodes on AWS instances, using rsyslog and logstash, i collect and store syslog events on elasticsearch index. till now everything was good…

---

## [Empty search term should not perform a search quers or should respond no results](https://discuss.elastic.co/t/empty-search-term-should-not-perform-a-search-quers-or-should-respond-no-results/346500)

<div class="topic-metadata">

**Author:** [@sebastianboelling](https://discuss.elastic.co/u/sebastianboelling)\
**Replies:** 1\
**Last updated:** [November 6, 2023, 9:44am UTC](https://discuss.elastic.co/t/empty-search-term-should-not-perform-a-search-quers-or-should-respond-no-results/346500 "2023-11-06T09:44:39Z")

</div>

Hi all, in my application we are using Search UI with App Search connector. The default behavior of Search UI seems to match all documents if an empty query is fired. Search API | App Search documentation \[8.10\] | Elas…

---

## [Sending cisco switch logs to elasticsearch](https://discuss.elastic.co/t/sending-cisco-switch-logs-to-elasticsearch/346458)

<div class="topic-metadata">

**Author:** [@laale1](https://discuss.elastic.co/u/laale1)\
**Replies:** 2\
**Last updated:** [November 6, 2023, 9:39am UTC](https://discuss.elastic.co/t/sending-cisco-switch-logs-to-elasticsearch/346458 "2023-11-06T09:39:36Z")

</div>

Hello community. I want to send my cisco switches logs to Elasticsearch, and we can't install elastic agent or beats to switches so what are the best ways we can send those logs to the elasticsearch.

---

## [Boolean should query wrong result](https://discuss.elastic.co/t/boolean-should-query-wrong-result/346381)

<div class="topic-metadata">

**Author:** [@Lukas\_Cern](https://discuss.elastic.co/u/Lukas_Cern)\
**Replies:** 1\
**Last updated:** [November 6, 2023, 9:14am UTC](https://discuss.elastic.co/t/boolean-should-query-wrong-result/346381 "2023-11-06T09:14:47Z")

</div>

Depending on order of queries, there is no match (wrong) or there is a match (correct). This wrong behavior is only the case of queryes containing one of synonyms. This is my index, data and explain queries: PUT /pokus…

---

## [Configuring Lifecycle on Elastic Agent](https://discuss.elastic.co/t/configuring-lifecycle-on-elastic-agent/346499)

<div class="topic-metadata">

**Author:** [@frappo](https://discuss.elastic.co/u/frappo)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 8:33am UTC](https://discuss.elastic.co/t/configuring-lifecycle-on-elastic-agent/346499 "2023-11-06T08:33:13Z")

</div>

Hi, I am experiencing an issue with the configuration of an index lifecycle policy for my logs. The policy work perfectly on the hot-warm phase, but indices never go to cold phase. There is something I am missing?

---

## [Best practice for adding/complement additional data to existing documents](https://discuss.elastic.co/t/best-practice-for-adding-complement-additional-data-to-existing-documents/346498)

<div class="topic-metadata">

**Author:** [@daniel-san](https://discuss.elastic.co/u/daniel-san)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 8:32am UTC](https://discuss.elastic.co/t/best-practice-for-adding-complement-additional-data-to-existing-documents/346498 "2023-11-06T08:32:12Z")

</div>

Hello there, we're only scratched the surface regarding the possibilities in Elasticsearch so the following question/example might be pretty basic: In our example we have multiple Hosts (VDI Workplaces) that are tied/o…

---

## [Could you please delete my account?](https://discuss.elastic.co/t/could-you-please-delete-my-account/346484)

<div class="topic-metadata">

**Author:** [@anon69830709](https://discuss.elastic.co/u/anon69830709)\
**Replies:** 2\
**Last updated:** [November 6, 2023, 8:07am UTC](https://discuss.elastic.co/t/could-you-please-delete-my-account/346484 "2023-11-06T08:07:49Z")

</div>

Could you please delete my account from the forum?

---

## [\[BUG\] Threatintel MISP Plugin runs in endless loop](https://discuss.elastic.co/t/bug-threatintel-misp-plugin-runs-in-endless-loop/344798)

<div class="topic-metadata">

**Author:** [@hti](https://discuss.elastic.co/u/hti)\
**Replies:** 1\
**Last updated:** [November 6, 2023, 7:44am UTC](https://discuss.elastic.co/t/bug-threatintel-misp-plugin-runs-in-endless-loop/344798 "2023-11-06T07:44:57Z")

</div>

Hello, we are running filebeat 8.8.1 and use the threatintel module to ingest data from MISP to elasticsearch. While it is running well most of the time, some MISP events (probably those with many attributes) will resu…

---

## [Queries regarding logsatsh configuration file](https://discuss.elastic.co/t/queries-regarding-logsatsh-configuration-file/346491)

<div class="topic-metadata">

**Author:** [@Ajay\_Kumar.S](https://discuss.elastic.co/u/Ajay_Kumar.S)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 6:16am UTC](https://discuss.elastic.co/t/queries-regarding-logsatsh-configuration-file/346491 "2023-11-06T06:16:45Z")

</div>

input { beats { port =\> "9006" } } filter { mutate { add\_field =\> { "beat\_version" =\> "%{\[beat\]\[version\]}" } } mutate { add\_field =\> { "log\_file" =\> "%{\[log\]\[file\]\[path\]}" } } mutate { add\_field =\> { "beat\_…

---

## [How to list top 5 IPs with their total usage in Mega Byte](https://discuss.elastic.co/t/how-to-list-top-5-ips-with-their-total-usage-in-mega-byte/346490)

<div class="topic-metadata">

**Author:** [@Indunil75](https://discuss.elastic.co/u/Indunil75)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 5:54am UTC](https://discuss.elastic.co/t/how-to-list-top-5-ips-with-their-total-usage-in-mega-byte/346490 "2023-11-06T05:54:32Z")

</div>

Hi Users, I have setup fortigate firewall with logstash, Elasticsearch and Kibana. It woks fine. In kibana, Dashboard, How to list top 5 IPs with their total usage in Mega Byte. How can I achieve it? Hope to hear from…

---

## [ELK v 7.6.0 Paloalto take certain types of logs](https://discuss.elastic.co/t/elk-v-7-6-0-paloalto-take-certain-types-of-logs/346479)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 2\
**Last updated:** [November 6, 2023, 5:12am UTC](https://discuss.elastic.co/t/elk-v-7-6-0-paloalto-take-certain-types-of-logs/346479 "2023-11-06T05:12:42Z")

</div>

Hello I am working with ELK v 7.6.0 I have asked the paloalto firewall administrator to send me the logs via Syslog on port 514 to my server where I have ELK. In the linux operating system in the path /etc/ the file r…

---

## [How can I get Gigabyte instead of number of records?](https://discuss.elastic.co/t/how-can-i-get-gigabyte-instead-of-number-of-records/346272)

<div class="topic-metadata">

**Author:** [@Indunil75](https://discuss.elastic.co/u/Indunil75)\
**Replies:** 1\
**Last updated:** [November 6, 2023, 4:34am UTC](https://discuss.elastic.co/t/how-can-i-get-gigabyte-instead-of-number-of-records/346272 "2023-11-06T04:34:02Z")

</div>

I have configured elasticsearch, kibana and logstash. fortigate firewall sends logs. While creating dashboard, It gives count of records. How can I get Gigabyte instead of count of records?

---

## [Integrate APM Logs Format to ELK](https://discuss.elastic.co/t/integrate-apm-logs-format-to-elk/346345)

<div class="topic-metadata">

**Author:** [@quoctuan2311](https://discuss.elastic.co/u/quoctuan2311)\
**Replies:** 8\
**Last updated:** [November 6, 2023, 3:37am UTC](https://discuss.elastic.co/t/integrate-apm-logs-format-to-elk/346345 "2023-11-06T03:37:50Z")

</div>

I have use ELK Stack to my system. My system have integrate my system logs format { "@timestamp": "2023-11-03T08:47:32.547Z", "log.level": "INFO", "message": "Schedule messages: size=1, markerTime=2023-11-03T15:4…

---

## [What is the best way to get AD authentication logs in ELK](https://discuss.elastic.co/t/what-is-the-best-way-to-get-ad-authentication-logs-in-elk/346482)

<div class="topic-metadata">

**Author:** [@ksrawat88](https://discuss.elastic.co/u/ksrawat88)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 3:01am UTC](https://discuss.elastic.co/t/what-is-the-best-way-to-get-ad-authentication-logs-in-elk/346482 "2023-11-06T03:01:25Z")

</div>

What is the best way to ingest AD authentication logs in ELK, through elastic agent or through audit beats .. we don’t want to impact AD server performance

---

## [Kibana-to-elastic: reason: unable to verify the first certificate](https://discuss.elastic.co/t/kibana-to-elastic-reason-unable-to-verify-the-first-certificate/346480)

<div class="topic-metadata">

**Author:** [@agvsap1](https://discuss.elastic.co/u/agvsap1)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 12:27am UTC](https://discuss.elastic.co/t/kibana-to-elastic-reason-unable-to-verify-the-first-certificate/346480 "2023-11-06T00:27:41Z")

</div>

Hi I have installed elasticsearch:8.5.1 and kibana:8.5.1 in gk1 with kubernetes 1.26. The kibana console when try to access elastic reports this error: We can’t establish a connection to Enterprise Search a…

---

## [Node Replacement Procedure](https://discuss.elastic.co/t/node-replacement-procedure/346478)

<div class="topic-metadata">

**Author:** [@digital-thought](https://discuss.elastic.co/u/digital-thought)\
**Replies:** 0\
**Last updated:** [November 5, 2023, 11:05pm UTC](https://discuss.elastic.co/t/node-replacement-procedure/346478 "2023-11-05T23:05:01Z")

</div>

Hi All, I have a multi-tier elastic cluster setup. My Hot tier is made up of 4 nodes. I need to replace one of these nodes with a completely new instance (machine). Can anyone recommend the best procedure to follow t…

---

## [Difference in sending static vs "live feeding" logs to logstash via filebeat](https://discuss.elastic.co/t/difference-in-sending-static-vs-live-feeding-logs-to-logstash-via-filebeat/346349)

<div class="topic-metadata">

**Author:** [@randomnamegenerator](https://discuss.elastic.co/u/randomnamegenerator)\
**Replies:** 2\
**Last updated:** [November 5, 2023, 7:50pm UTC](https://discuss.elastic.co/t/difference-in-sending-static-vs-live-feeding-logs-to-logstash-via-filebeat/346349 "2023-11-05T19:50:06Z")

</div>

We have two different ELK servers which are used to analyse logs from our own application, one is in-house and the other is on the customers site. We have different pipelines for the application itself and then also for …

---

## [Moving self hosted elasticsearch in ec2 instance to upgrade enterprise level subscription](https://discuss.elastic.co/t/moving-self-hosted-elasticsearch-in-ec2-instance-to-upgrade-enterprise-level-subscription/346464)

<div class="topic-metadata">

**Author:** [@Abdul\_Rajak](https://discuss.elastic.co/u/Abdul_Rajak)\
**Replies:** 1\
**Last updated:** [November 5, 2023, 4:59pm UTC](https://discuss.elastic.co/t/moving-self-hosted-elasticsearch-in-ec2-instance-to-upgrade-enterprise-level-subscription/346464 "2023-11-05T16:59:37Z")

</div>

Currently we have hosted self hosted elasticsearch with kibana through Ec2 instance.We are planning to get subscription for enterprise support. I'm new to elasticsearch. can someone suggest what are the measures i need …

---

## [Elasticsearch fails to start after reboot](https://discuss.elastic.co/t/elasticsearch-fails-to-start-after-reboot/346462)

<div class="topic-metadata">

**Author:** [@gisly](https://discuss.elastic.co/u/gisly)\
**Replies:** 1\
**Last updated:** [November 5, 2023, 3:15pm UTC](https://discuss.elastic.co/t/elasticsearch-fails-to-start-after-reboot/346462 "2023-11-05T15:15:50Z")

</div>

I am running the following version of Elasticsearch "version" : { "number" : "7.12.0", "build\_flavor" : "default", "build\_type" : "rpm", "build\_hash" : "78722783c38caa25a70982b5b042074cde5d3b3a", "b…

---

## [Why there are not any index on elasticsearch after run filebeat](https://discuss.elastic.co/t/why-there-are-not-any-index-on-elasticsearch-after-run-filebeat/346422)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 9\
**Last updated:** [November 5, 2023, 2:43pm UTC](https://discuss.elastic.co/t/why-there-are-not-any-index-on-elasticsearch-after-run-filebeat/346422 "2023-11-05T14:43:56Z")

</div>

My elasticsearch version = 8.10.4 My filebeat version : 8.7 Also these are outputs : filebeat test output elasticsearch: https://172.10.110.29:9200... parse url... OK connection... parse host... OK dns loo…

---

## [How can create separate filestream with custom name when using filebeat](https://discuss.elastic.co/t/how-can-create-separate-filestream-with-custom-name-when-using-filebeat/346461)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 0\
**Last updated:** [November 5, 2023, 1:55pm UTC](https://discuss.elastic.co/t/how-can-create-separate-filestream-with-custom-name-when-using-filebeat/346461 "2023-11-05T13:55:55Z")

</div>

I want to create separate filestream for APP-Logs with specific name "APP-LOGS" when I am run filebeat. How can do it ? What is configuration in filebeat.yml ?

[Previous page](https://discuss.elastic.co/latest.md?page=490)

[Next page](https://discuss.elastic.co/latest.md?page=492)
